CVE-2026-15172
Wireshark vulnerability analysis and mitigation

Overview

CVE-2026-15172 is a denial-of-service vulnerability in the FMP/NOTIFY protocol dissector of Wireshark, caused by improper handling of loop conditions when parsing malicious network capture files. It affects Wireshark versions 4.6.0 through 4.6.6 and 4.4.0 through 4.4.16. The vulnerability was published on July 8, 2026, with patches available in versions 4.6.7 and 4.4.17. It carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified under CWE-606 (Unchecked Input for Loop Condition) and CWE-1286 (Improper Validation of Syntactic Correctness of Input), meaning the FMP/NOTIFY dissector fails to properly validate packet data used to control loop execution, potentially resulting in an infinite loop. Exploitation requires a local attacker to craft a malicious pcap file and have a user open it in Wireshark or TShark; the attack vector is local with no privileges required but user interaction is necessary. A proof-of-concept was published on the Wireshark GitLab issue tracker, including specific malicious pcap files (dos.pcap, overflow.pcap) and a PowerShell command to trigger the infinite loop DoS (Wireshark GitLab, GitHub Advisory).

Impact

Successful exploitation causes Wireshark or TShark to crash or enter an infinite loop, resulting in a complete loss of availability for the application. There is no impact on confidentiality or data integrity, as the vulnerability is limited to a denial-of-service condition. The scope is confined to the affected Wireshark process and does not enable lateral movement or data exfiltration (GitHub Advisory, Red Hat Bugzilla).

Exploitation steps

  1. Craft or obtain a malicious capture file: Create or download a specially crafted pcap file (dos.pcap) containing a malformed FMP/NOTIFY protocol packet designed to trigger an unchecked loop condition in the dissector.
  2. Deliver the file to the target: Social-engineer a user into opening the malicious pcap file, or place it in a location where the target user is likely to open it with Wireshark or TShark.
  3. Trigger the DoS: The user opens the file in Wireshark (GUI) or via TShark (CLI). For TShark, the PoC uses the command: Start-Process "C:\Program Files\Wireshark\tshark.exe" "-r dos.pcap" on Windows.
  4. Application crash/hang: The FMP/NOTIFY dissector enters an infinite loop or crashes, rendering Wireshark/TShark unavailable for the duration of the session (Wireshark GitLab).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced pcap files (e.g., dos.pcap, overflow.pcap) in user download directories or shared network locations.
  • Process: Wireshark or TShark process consuming 100% CPU for an extended period without completing analysis; process requiring forced termination.
  • Logs: Application crash logs or Windows Event Logs showing abnormal termination of wireshark.exe or tshark.exe shortly after opening a specific capture file.

Mitigation and workarounds

Update Wireshark to version 4.4.17 or 4.6.7 (or later) to remediate the vulnerability (Wireshark Security, GitHub Advisory). As a workaround until patching is complete, restrict untrusted users from opening capture files in Wireshark and avoid opening pcap files from untrusted or unknown sources. Fedora and other Linux distributions have also issued updated packages addressing this vulnerability.

Community reactions

Red Hat tracked the issue via Bugzilla (Bug 2498306) and assigned it medium severity, with the bug filed by the OSIDB automated import system (Red Hat Bugzilla). Fedora issued updated Wireshark packages addressing this and related vulnerabilities, with coverage noted on Linux security news sites. No significant independent researcher commentary or broad social media discussion has been identified for this vulnerability.

Additional resources


SourceThis report was generated using AI

Related Wireshark vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15174MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026
CVE-2026-15173MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoYesJul 08, 2026
CVE-2026-15172MEDIUM5.5
  • Wireshark logoWireshark
  • wireshark
NoYesJul 08, 2026
CVE-2026-15171MEDIUM5.5
  • Wireshark logoWireshark
  • cpe:2.3:a:wireshark:wireshark
NoYesJul 08, 2026
CVE-2026-15168LOW3.3
  • Wireshark logoWireshark
  • wireshark-cli
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management